Skip to content

Keep session feedback responsive and enforce scoped tool approvals - #654

Merged
igorcosta merged 2 commits into
mainfrom
feedback-issue-fixes
Oct 9, 2026
Merged

igorcosta merged 2 commits into
mainfrom
feedback-issue-fixes

Conversation

@igorcosta

@igorcosta igorcosta commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Session feedback should leave the composer usable, and argument-scoped tool approvals must be checked against the command or path that will actually run. This change adds an optional five-point survey above the composer, renders voting choices directly below its question, preserves drafts, and enforces concrete tool scopes. Timed auto-approval restores the prior permission settings when it expires.

  • Send /feedback <message> and /bug / /bug-report submissions in the background with redacted session diagnostics, optional GitHub identity, and anonymous reporting support.
  • Save hook toggles in order before the command returns, so the next prompt sees the updated hooks and completion messages reflect persisted settings.
  • Recheck settled terminal frames, close failed startup sessions, and wait for child exit before removing fixtures. Mock the mobile pairing fixture's relay and startup requests to avoid external DNS keeping the test CLI alive.
  • Add an opt-in full-proof label workflow that runs the complete proof on a GitHub runner.
  • Include the reviewed dependency refresh. Ink remains 7.1.1 and React remains 19.3.

Validation:

  • Test-first regressions cover voting below the question, transient terminal redraws, failed startup cleanup, asynchronous hook saves, and external requests escaping the mobile pairing fixture.
  • bun run proof passed in GitHub CI for commit 33192ed800b9a27ff658de51f68204f0d3687430: 11,352 unit tests passed (38 skipped), followed by all 57 terminal test files passing with 253 tests passed (3 skipped). No failures. This includes lint, typechecking, and the production build.
  • Both the pull-request CI run and branch CI run passed all 11 jobs, including Linux, macOS, and Windows builds and every terminal shard. All 23 checks are green, including Full proof.
  • Native macOS ad-hoc signing and archive verification also passed locally with the manifest-pinned Bun 1.4.2. Existing platform and conditional skips remain; the failure repairs do not disable tests.

The provider incidents reviewed alongside this work remain separate: findings were posted on all 26 open reports, and only identical duplicates #627 and #629 were closed in favor of #628 and #630. This PR does not resolve the remaining OpenAI compatibility, missing-tool-result, Autohand safety-check, or Azure authentication reports.

Render the five-point voting choices directly below the survey question,
preserve drafts, and send feedback and redacted bug reports in the background.
Evaluate command and path scopes with concrete arguments, restore permissions
after timed auto-approval, and include the reviewed dependency refresh.

Co-authored-by: Autohand Evolve <code-noreply@autohand.ai>
@igorcosta igorcosta added the full-proof Run the complete lint, unit, build, and terminal proof on GitHub label Oct 8, 2026
Persist hook toggles in order before returning from the command or reporting
success. Recheck settled Tuistory frames, close failed startup sessions,
and wait for child exit before removing terminal fixtures.

Keep mobile pairing tests independent of external relay and startup APIs.
Integrate upstream peer selection synchronization and release validation.
Add an opt-in GitHub job for full proof on an uninterrupted runner.

Co-authored-by: Autohand Evolve <code-noreply@autohand.ai>
@igorcosta
igorcosta marked this pull request as ready for review October 9, 2026 00:53
@igorcosta
igorcosta merged commit 4597ad0 into main Oct 9, 2026
23 checks passed
igorcosta added a commit that referenced this pull request Oct 9, 2026
)

Render feedback voting directly below its question and preserve composer drafts. Enforce concrete tool scopes and restore prior permissions when timed auto-approval expires.

Persist hook toggles before reporting completion, repair terminal-session startup and cleanup races, and isolate mobile pairing fixtures from external requests. Include the reviewed dependency refresh and optional full-proof workflow.

Validation: all 23 checks passed, including complete bun run proof in GitHub CI.

Co-authored-by: Autohand Evolve <code-noreply@autohand.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

full-proof Run the complete lint, unit, build, and terminal proof on GitHub

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant